For the complete documentation index, see llms.txt. This page is also available as Markdown.

Risk Detections

This report lists the risk detections Microsoft Entra ID Protection has raised, with the most recent first. Each row is a single detection rather than a user, so one account under investigation may appear several times with different detection types and timings.

Table Details

The properties returned are for the Graph resource type riskDetection. For more information on the properties please see the Graph documentation.

The Location column is a button rather than plain text. Selecting it opens a Location Details dialog plotting the detection on a map, with the city, state and country listed alongside, which is usually the quickest way to judge whether a detection is a genuine anomaly or the user travelling.

Filters

Filter
Shows

Users at Risk

Detections still open and not yet acted on.

Confirmed Compromised

Detections an administrator has confirmed as a genuine compromise.

Confirmed Safe

Detections an administrator has marked as legitimate activity.

Remediated

Detections resolved by the user meeting a remediation requirement, such as a self-service password reset.

Table Actions

Action
Description
Bulk Action Available

Research Compromised Account

Opens the Compromise Remediation tab for the account the detection relates to, where the usual indicators of compromise are gathered in one place.

More Info

Opens the Extended Info flyout with the full details for the selected row.

Risk state is held against the user rather than the individual detection, so marking a user as safe or compromised in Entra ID Protection changes the state shown on every detection for that account. The Risky Users page is where a user's overall risk is reviewed and dismissed.


Feature Requests/Ideas

We value your feedback and ideas. Please raise any feature requests on GitHub.

Last updated

Was this helpful?